CVE-2023-45820
Directus crashes on invalid WebSocket message
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could leverage this bug to crash Directus. This issue has been addressed in version 10.6.2. Users are advised to upgrade. Users unable to upgrade should avoid using websockets.
Directus es una API y un panel de aplicaciones en tiempo real para administrar el contenido de la base de datos SQL. En las versiones afectadas, cualquier instalación de Directus que tenga websockets habilitados puede fallar si el servidor websocket recibe un frame no válido. Un usuario malintencionado podría aprovechar este error para bloquear Directus. Este problema se solucionó en la versión 10.6.2. Se recomienda a los usuarios que actualicen. Los usuarios que no puedan actualizar deben evitar el uso de websockets.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-10-13 CVE Reserved
- 2023-10-19 CVE Published
- 2024-09-12 CVE Updated
- 2024-09-12 First Exploit
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/directus/directus/security/advisories/GHSA-hmgw-9jrg-hf2m | 2024-09-12 |
URL | Date | SRC |
---|---|---|
https://github.com/directus/directus/commit/243eed781b42d6b4948ddb8c3792bcf5b44f55bb | 2023-10-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Monospace Search vendor "Monospace" | Directus Search vendor "Monospace" for product "Directus" | >= 10.4.0 < 10.6.2 Search vendor "Monospace" for product "Directus" and version " >= 10.4.0 < 10.6.2" | node.js |
Affected
|